Direct Answer
SOC 2 and ISO 27001 auditors don't review every offboarding, they sample a handful of departures from the past 12 months and ask for a timestamped log proving exactly when access was revoked, by whom, and across which systems. Most companies can prove this for email and the identity provider, but not for SaaS tools outside SSO or API tokens, which is the most common finding auditors write up. deeploi generates this evidence automatically at the moment access is revoked, so the audit trail already exists when the sample request comes in.
Key Takeaways
- Auditors sample, they don't audit everything: SOC 2 Type II and ISO 27001 auditors typically pull five or so former employees from the past year and ask for proof of full revocation, not a policy document describing what should happen.
- "Zombie accounts" are the most common finding: logins that stay active long after someone leaves, usually because they live in a tool outside the identity provider and nobody checked.
- The evidence window is narrower than most companies assume: frameworks generally expect revocation within 24 hours, and auditors check the gap between the exit date and the revocation timestamp, not just whether it eventually happened.
- A policy is not evidence: auditors want a timestamped log naming what was revoked, when, and by whom, for the specific people they sampled, not a general offboarding procedure.
- deeploi generates the audit trail as a byproduct of offboarding itself: every revocation is logged automatically, so producing evidence for a sample doesn't require reconstructing anything after the fact.
An auditor reviewing a company's SOC 2 Type II report doesn't ask to see the offboarding policy. They pick five people who left in the past year and ask for proof: when was each account disabled, by whom, and across which systems. One company can answer for email. Fewer can answer for the CRM, the code repository, or the API key someone generated eighteen months ago. This gap has a name in security circles, zombie accounts, and it's the single most common finding in access-control audits. deeploi, the all-in-one IT management platform for growing companies, builds the evidence trail into the offboarding process itself, so producing it for a sample isn't a scramble. This article walks through what auditors actually sample, what they expect to see, and why most companies can prove less than they think.

SOC 2 and ISO 27001, in Plain Terms
SOC 2 is a US-originated auditing standard that certifies how well a company protects customer data, covering principles like security and availability. It's frequently required by American enterprise customers before they'll sign a contract, which is why it comes up so often for scale-ups selling into the US. ISO 27001 is an international standard for an information security management system, and it's the more common baseline expectation in Europe, including much of the DACH market. Both require an independent auditor to test whether a company's security controls, offboarding included, actually hold up in practice, not just whether they look reasonable on paper.
Why Auditors Sample Instead of Reviewing Everything
Neither SOC 2 Type II nor ISO 27001 audits check every employee departure. Reviewing a full year of offboardings for every client would make audits impossibly slow, so auditors use sampling instead: they pull a handful of departures, usually around five, from the population of people who left in the audit period, and treat that sample as representative of the whole process.
This changes what actually matters. A company doesn't need to prove its offboarding process is theoretically sound. It needs to produce specific, timestamped evidence for the specific people the auditor happened to sample. If the process worked for four of the five but the fifth has a gap, that gap becomes a documented exception in the audit report, regardless of how solid the other four look.
For each sampled departure, auditors typically request:
- A timestamped log showing exactly when the account was disabled
- Confirmation that software licenses tied to that person were removed
- Evidence that company hardware was recovered or accounted for
- A named individual responsible for carrying out the revocation
Producing this after the fact, months after someone left, is where most companies run into trouble. The information technically exists somewhere, in a ticketing system, an email thread, someone's memory, but assembling it into a clean, timestamped answer for one specific person is slow and often incomplete.
What Auditors Actually Ask For
The table below reflects what a typical SOC 2 or ISO 27001 sample request looks like, and where companies most often come up short.
Notice what's absent from this list: a policy document. Auditors already assume most companies have one. What they're testing is whether the policy was actually followed for the specific people they picked, which is a very different bar.
{{cta}}
SOC 2 vs. ISO 27001: What Each Framework Expects
The two frameworks overlap heavily on offboarding, but they're not identical in how they sample and what they weigh most heavily.
The practical takeaway is the same either way: both frameworks expect a defined timeframe and specific, per-person evidence, not a general assurance that offboarding "works."
Zombie Accounts and Orphan Secrets: Why the Same Gaps Keep Showing Up
Two terms come up repeatedly once you're looking at this from an audit perspective rather than an IT perspective.
A zombie account is a login that stays active long after the person who used it has left, usually in a tool that sits outside the identity provider and therefore doesn't get touched when the main account is disabled. An orphan secret is the machine-credential version of the same problem: an API key, personal access token, or OAuth grant that keeps authenticating independently of any human login, often created by someone who has since left and forgotten it existed.
Neither shows up in a routine check. They surface only when someone specifically goes looking, which in practice usually means either a security incident or an audit sample. That's exactly why they're the finding auditors write up most often: not because companies are careless, but because these gaps are invisible by default.
Automating the Evidence, Not Just the Offboarding
Manually running an offboarding checklist can revoke access correctly and still leave you without usable audit evidence, because the proof of what happened often lives across several tools, tickets, and people's memory instead of one record.
deeploi ties access revocation to a single offboarding event and logs every step automatically: what was revoked, when, and by whom. When an audit sample request comes in, the evidence already exists in the same form the auditor expects, rather than needing to be reconstructed from scattered sources under time pressure. Companies using deeploi report up to 98% less IT workload on tasks like this, largely because the audit trail is a byproduct of the process rather than a separate project.
Conclusion
An offboarding process can work perfectly and still fail an audit, if nobody can produce evidence for the specific people sampled. The gap is rarely dishonesty, it's that proof lives in scattered tools instead of one record. deeploi builds that record automatically, so the evidence is ready before the sample request ever arrives.
Your IT in the best hands. See how deeploi works
FAQ
What is a zombie account in an audit context?
A zombie account is a login that remains active long after the person who used it has left the company, usually because it lives in a tool outside the identity provider and wasn't checked during offboarding.
How many former employees do SOC 2 auditors typically sample?
There's no fixed number in the standard itself, but auditors commonly pull around five departures from the audit period as a representative sample, rather than reviewing every termination.
What evidence do auditors expect for access revocation?
A timestamped log showing what was revoked and when, confirmation that licenses were removed, a named person responsible, and evidence covering both human accounts and machine credentials like API keys.
What happens if a company can't produce revocation evidence during an audit?
It typically becomes a documented exception in a SOC 2 report or a nonconformity under ISO 27001, which can require a corrective action plan and may affect certification timelines.
Does ISO 27001 require the same evidence as SOC 2?
The two overlap significantly, both expect timely, documented revocation, but ISO 27001 ties evidence more directly to a documented procedure under the certified management system, while SOC 2 focuses on operating effectiveness across the audit period.







%402x.png)


